Staff Application Security Engineer
Core
Define and drive application and product security architecture for a cloud-native SaaS platform, embedding security into the SDLC and securing AI/agentic technologies.
Role type
Staff Application Security Engineer (Technical Lead)
Builds
Cloud-native SaaS platform, AI agents, and multi-agent systems
Domain
Enterprise SaaS, Cloud Security, AI/LLM Security
Deliverable
production ML models | product features | infrastructure
Required skills
Application security architecture, Secure SDLC, Shift-left security, CI/CD pipeline security, Threat modeling, API security, AI security guardrails, Penetration testing, Secure coding practices, Cloud security (AWS/GCP/Azure), Kubernetes security, Burp Suite Pro, Wiz
Preferred skills
LLM application security, AppSec automation/orchestration, Commercial AppSec platforms (Veracode, Checkmarx), Vulnerability management programs, SOC 2/HITRUST/ISO 27001 frameworks, ML/AI for security detection
Technologies
Java, Spring Boot, JavaScript, Node.js, C#, Microservices, Serverless, Jenkins, ArgoCD, SAST/SCA/DAST tools, Wiz, AWS, GCP, Azure, Kubernetes, Burp Suite Pro
Responsibilities
Define application/product security strategy and roadmap, Mentor engineering and security staff, Lead threat modeling and risk assessments, Integrate security into CI/CD pipelines, Conduct penetration testing and validate remediation, Establish AI security guardrails and MCP standards
Seniority
Staff, hands-on IC with technical leadership